Foundations
The Limitations of Identity-Centric Governance
1 min readEdit on GitHub
- Static and Coarse-Grained: Traditional Role-Based Access Control (RBAC) and other identity-centric models are often too static and coarse-grained to handle the dynamic nature of modern applications.
- Poor Fit for Non-Human Agents: The lifecycle of agentic software (e.g., CI/CD pipelines, bots, IoT devices) is fundamentally different from that of human users, a problem that is being amplified by the rise of agentic AI.
- Focus on "Who" not "What": These models primarily focus on who is accessing a resource, rather than what is being done with it. This makes it difficult to reason about the actual risk of an operation.

